Skip to content
2026

Now taking on 4 new clients this year — white-glove onboarding, month to month.

Book a call

Cybersecurity Tabletop Exercises: 10 Questions Owners Ask

A conference room table mid-session during a cybersecurity tabletop exercise, covered with printed scenario documents, sticky notes, coffee cups and a notepad, with a whiteboard and empty chairs behind it

A tabletop exercise is a meeting where you walk your team through a cyberattack on paper and find out what your plan actually does. It costs a conference room and two hours, and it's the cheapest way to discover that the person who holds your backup credentials left in March.

Here are the questions owners ask us before they run their first one.

Tabletop exercise questions owners ask

What is a cybersecurity tabletop exercise?

A facilitated discussion, not a technical test. Somebody reads out a scenario — ransomware note on the file server, say — and the people who'd have to respond talk through what they'd each do, step by step. Nothing gets unplugged and no systems are touched. The output is a list of things that don't work.

How long should it take?

Two hours for a first one. Ninety minutes of scenario and half an hour of debrief is enough to expose the big gaps without losing the room. Longer sessions get diminishing returns fast, because the same three problems keep surfacing. Run a short one this quarter rather than scheduling a half-day you'll postpone twice.

Who needs to be in the room?

The owner or a decision-maker, whoever handles IT, whoever handles money, and whoever would talk to customers. That last one gets skipped constantly and it's the one that hurts — someone has to answer the phone while the servers are down. Keep it under eight people. Your IT provider should facilitate, not answer for you.

What scenario should we run first?

Ransomware. It's the one that puts every part of the business on the table at once: backups, insurance, payroll, customer notification, and whether you can operate at all on day two. CISA's tabletop exercise packages cover ransomware, phishing, insider threats and industrial control system compromise, with more than 100 packages available.

Do we need a written incident response plan first?

No, and waiting for one is how this gets deferred forever. Running the exercise is often the fastest way to write the plan, because the gaps it exposes become the plan's contents. If you already have a documented incident response plan, bring it and test whether it survives contact with a real scenario.

How often should we run one?

Annually at minimum, and again after anything that changes who does what — a new IT provider, an acquisition, losing the person who knew where everything was. Rotate the scenario so you're not rehearsing the same answer. The second exercise is usually more useful than the first, because people stop performing and start arguing about specifics.

What does a tabletop exercise cost?

Less than most owners assume. CISA offers its exercise packages to stakeholders on request, so the real cost is mostly the time of the people in the room plus a facilitator if you use one. Compare that to what slow response costs: IBM found organizations took a mean of 241 days to identify and contain a breach — the lowest that figure has been in nine years.

Does cyber insurance or compliance require one?

Requirements vary by carrier and framework, so read your own policy rather than trusting a general answer. What's consistent is direction of travel: in the renewal applications we've reviewed over the past two years, carriers increasingly ask about response readiness, and NIST's current incident response guidance, SP 800-61 Revision 3 (April 2025) frames preparedness as ongoing risk management rather than a document you file.

What should come out of it?

A short written list, assigned to named people with dates. Not a report nobody reads. If the exercise surfaced that nobody's tested a restore in a year, that's one line with an owner and a deadline. CISA's packages include after-action report templates for exactly this. An exercise with no follow-up list was a conversation, not an exercise.

What usually goes wrong in the first one?

The same handful of things, almost every time. Nobody knows who declares an incident. The backup story is more confident than the last actual restore test justifies. The cyber insurance policy number lives in an inbox on an encrypted machine. And the contact list for staff is a spreadsheet on the file server that just got encrypted.

Sources and further reading

If you've never run one, the first exercise is the one that finds the most. Book a complimentary session and we'll facilitate a two-hour tabletop against your environment, then hand you the gap list. It sits alongside our incident response and security assessment work.

By Joel Baum, who leads cybersecurity, compliance and security strategy at The NetSys Group. NetSys has delivered managed IT, cybersecurity, and cloud services since 1998 to businesses across NY, NJ, CT, PA, and Southwest Florida.

Reading is free. So is knowing where you stand.

Turn insight into action.

Take a free cybersecurity or AI readiness assessment, or book a call with a NetSys engineer — no obligation, no runaround.